Windows Named Pipe to AD FS WID SQL Query Path by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
FreeUnreviewedSigmamediumv1
windows-named-pipe-to-ad-fs-wid-sql-query-path-by-uncommon-process-1ea13e8c
title: Windows Named Pipe to AD FS WID SQL Query Path by Uncommon Process
id: 1bc49183-d440-4539-9fc5-68f28a922d76
status: test
description: This rule flags creation of a named pipe connection to the AD FS Windows Internal Database (WID) SQL query endpoint. Attackers may use local named-pipe access to read AD FS configuration data that can be sensitive for SAML token signing. The detection relies on Windows named pipe creation telemetry (e.g., Sysmon pipe events) and correlates the PipeName with the creating process path while excluding a set of known benign binaries.
references:
- https://github.com/Azure/Azure-Sentinel/blob/f99542b94afe0ad2f19a82cc08262e7ac8e1428e/Detections/SecurityEvent/ADFSDBNamedPipeConnection.yaml
- https://o365blog.com/post/adfs/
- https://github.com/Azure/SimuLand
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/pipe_created/pipe_created_adfs_namedpipe_connection_uncommon_tool.yml
author: Roberto Rodriguez @Cyb3rWard0g, Huntrule Team
date: 2021-10-08
modified: 2023-11-30
tags:
- attack.collection
- attack.t1005
logsource:
product: windows
category: pipe_created
definition: Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
detection:
selection:
PipeName: \MICROSOFT##WID\tsql\query
filter_main_generic:
Image|endswith:
- :\Windows\System32\mmc.exe
- :\Windows\system32\svchost.exe
- :\Windows\System32\wsmprovhost.exe
- :\Windows\SysWOW64\mmc.exe
- :\Windows\SysWOW64\wsmprovhost.exe
- :\Windows\WID\Binn\sqlwriter.exe
- \AzureADConnect.exe
- \Microsoft.Identity.Health.Adfs.PshSurrogate.exe
- \Microsoft.IdentityServer.ServiceHost.exe
- \Microsoft.Tri.Sensor.exe
- \sqlservr.exe
- \tssdis.exe
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 1ea13e8c-03ea-409b-877d-ce5c3d2c1cb3
type: derived
What it detects
This rule flags creation of a named pipe connection to the AD FS Windows Internal Database (WID) SQL query endpoint. Attackers may use local named-pipe access to read AD FS configuration data that can be sensitive for SAML token signing. The detection relies on Windows named pipe creation telemetry (e.g., Sysmon pipe events) and correlates the PipeName with the creating process path while excluding a set of known benign binaries.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.